Improper control of a resource through its lifetime in Linux kernel - CVE-2026-97615

 

Improper control of a resource through its lifetime in Linux kernel - CVE-2026-97615

Published: September 28, 2026


Vulnerability identifier: #VU152591
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-97615
CWE-ID: CWE-664
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local privileged user to corrupt list state on another bridge.

The vulnerability exists due to reuse of a global frame-type handler list node in the Linux bridge CFM and MRP frame handlers when enabling a protocol on multiple bridges and unregistering it on one bridge. A local privileged user can create protocol instances on multiple bridges and remove an instance from one bridge to corrupt list state on another bridge.


Affected software

Linux kernel

How to mitigate CVE-2026-97615

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins